CVE-2007-1747
Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a malformed drawing object, which triggers memory corruption.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 31.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a malformed drawing object, which triggers memory corruption.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 31.56% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- microsoft/office
- Source
- secure@microsoft.com
References
- http://secunia.com/advisories/25178Vendor Advisory
- http://www.kb.cert.org/vuls/id/853184US Government Resource
- http://www.osvdb.org/34396
- http://www.securityfocus.com/archive/1/468871/100/200/threaded
- http://www.securityfocus.com/bid/23826
- http://www.securitytracker.com/id?1018014
- http://www.us-cert.gov/cas/techalerts/TA07-128A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/1710
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-025
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33908
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2051
- http://secunia.com/advisories/25178Vendor Advisory
- http://www.kb.cert.org/vuls/id/853184US Government Resource
- http://www.osvdb.org/34396
- http://www.securityfocus.com/archive/1/468871/100/200/threaded
- http://www.securityfocus.com/bid/23826
- http://www.securitytracker.com/id?1018014
- http://www.us-cert.gov/cas/techalerts/TA07-128A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/1710
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-025
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33908
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2051
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.